{"id":"GHSA-7f4j-64p6-5h5v","aliases":["GO-2024-2726"],"title":"Traefik affected by HTTP/2 CONTINUATION flood in net/http","summary":"Traefik affected by HTTP/2 CONTINUATION flood in net/http","severity":"medium","vendor":"traefik","product":"github.com/traefik/traefik/v2","ecosystem":"go","affected":["github.com/traefik/traefik/v2 < 2.11.2","github.com/traefik/traefik/v3 >= 3.0.0-rc1, < 3.0.0-rc5"],"patched":["github.com/traefik/traefik/v2 2.11.2","github.com/traefik/traefik/v3 3.0.0-rc5"],"published":"2024-04-15","updated":"2026-08-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-7f4j-64p6-5h5v","references":[{"url":"https://github.com/traefik/traefik/security/advisories/GHSA-7f4j-64p6-5h5v"},{"url":"https://github.com/traefik/traefik"},{"url":"https://github.com/traefik/traefik/releases/tag/v2.11.2"},{"url":"https://github.com/traefik/traefik/releases/tag/v3.0.0-rc5"}],"tags":["osv","go"],"ingestedAt":"2026-08-07T19:14:16.080Z","slug":"GHSA-7f4j-64p6-5h5v","body":"## Overview\n\nThere is a potential vulnerability in Traefik managing HTTP/2 connections.\n\nMore details in the [CVE-2023-45288](https://www.cve.org/CVERecord?id=CVE-2023-45288).\n\n## Patches\n\n- https://github.com/traefik/traefik/releases/tag/v2.11.2\n- https://github.com/traefik/traefik/releases/tag/v3.0.0-rc5\n\n## Workarounds\n\nNo workaround\n\n## For more information\n\nIf you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).\n\n## Affected packages\n\n- `github.com/traefik/traefik/v2 < 2.11.2`\n- `github.com/traefik/traefik/v3 >= 3.0.0-rc1, < 3.0.0-rc5`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/traefik/traefik/v2 2.11.2`\n- `github.com/traefik/traefik/v3 3.0.0-rc5`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}